ThreatHunting icon indicating copy to clipboard operation
ThreatHunting copied to clipboard

Documentation to Add more TTP's?

Open DerF66 opened this issue 1 year ago • 1 comments

I want to add more TTP's, is there any documentation available on how one can add more to this tool? It seems the saveconference file is the file to edit.

DerF66 avatar May 16 '23 00:05 DerF66

You are on the right track with observation that Signature of TTP would ultimately get expressed as scheduled search in savedsearches.conf. There is another GitHub project called Sigma where you can find newer signatures for TTPs and convert them to splunk searches. If you are looking to include signatures observed from sources other than sysmon, powershell or windows event logs there will of course by many more conf files to update in the app such as macros, inputs, and possibly props and transforms.

dstaulcu avatar May 17 '23 01:05 dstaulcu